>
> Yeah, sorry for the terminology there. I was still thinking of composites.
> If the server supports just one composite for which it has a certificate,
> say PQi+Tj, then this is every possible composite out of the one-element
> set {PQi} and the one-element set {Tj}.
> In general, I believe this to be the common case for servers (and the
> worst case for interop), and expect a larger number of algorithms to be
> supported at the client.
>

Ah, ok, so this kinda works for the leafs, but goes wrong for the
signatures up the chain—see my other mail 2 hours ago.
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to